What evidence may identify the data that left?¶
The practical answer¶
Identifying the data that left requires linking the source information to the transferred content or destination record.
The key evidential caution¶
The dangerous assumption is that a large transfer allows investigators to infer exactly which files were taken.
It may not.
Relevant evidence¶
Useful evidence may include:
Key points¶
- archive contents
- file hashes
- upload manifests
- provider object metadata
- message attachments
- file-transfer logs
- database export records
- cloud audit events
- removable-media contents
- recipient copies
- staging-folder records
Investigators should compare:
- filenames
- sizes
- hashes
- timestamps
- object identifiers
- folder structure
- export parameters
- source and destination records
The source data may have been compressed, encrypted, renamed, split or combined.
That can make one-to-one comparison difficult.
Evidential limits¶
Do not assume that every file in a staging folder was transferred.
Likewise, do not assume that a destination object contains the same content merely because its name matches.
Where the exact content cannot be established, report the supported scope or category rather than inventing precision.
Where exact files cannot be identified, other evidence may establish a narrower category, such as a named mailbox, database table or project folder. The report should distinguish confirmed items, likely included material and data merely present in the same source location.
Partial recovery can still establish a minimum scope. For example, one confirmed document within an archive proves at least that item was included, while the remainder may remain unknown.
Do not expand that minimum into the whole suspected dataset without support.
Operational takeaway¶
Link source and destination content through hashes, metadata, manifests or recovered copies, and report uncertainty where the exact data cannot be proved.